PT-2019-9223 · Tp Link · Tp-Link Wr1043N
Published
2019-06-20
·
Updated
2020-08-24
·
CVE-2018-16119
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link WR1043nd version 3
Description
The issue is a stack-based buffer overflow in the httpd server, allowing remote attackers to execute arbitrary code via a malicious MediaServer request to "/userRpm/MediaServerFoldersCfgRpm.htm".
Recommendations
For TP-Link WR1043nd version 3, consider disabling access to the "/userRpm/MediaServerFoldersCfgRpm.htm" endpoint until a patch is available. Restrict access to the MediaServer functionality to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Wr1043N